Anonymous Credential Enrollment for Secure DSN Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current dispersed storage networks face challenges in securely and reliably storing and retrieving data across multiple geographically distributed storage units, particularly in ensuring data integrity and availability without redundant copies, while also managing access for both authenticated and anonymous users.

Innovation Solution

The implementation of a dispersed storage network (DSN) that utilizes error encoding techniques like Cauchy Reed-Solomon encoding to distribute data across multiple storage units, along with a managing unit that handles user authentication, billing, and network operations, and an integrity processing unit that rebuilds corrupted data slices, while allowing anonymous users temporary access through a computational and Turing challenge-based enrollment process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data is distributed across multiple geographically dispersed storage units using error encoding, then data availability and reliability are improved, but system complexity increases

Engineering Contradiction:
Improvedata availabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments data into multiple encoded slices distributed across geographically dispersed storage units. Each storage unit holds a portion of the encoded data, and the system can reconstruct the original data from any sufficient subset of these slices, thereby improving reliability while managing complexity through modular distribution

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an integrity processing unit as an intermediary that manages the complexity of error encoding and data reconstruction. This intermediary handles the computational burden of Cauchy Reed-Solomon encoding and decoding, shielding the distributed storage units from complex processing while maintaining high reliability

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If anonymous users are granted temporary access to the dispersed storage network, then accessibility and ease of operation are improved, but security risks increase

Engineering Contradiction:
ImproveaccessibilityVSAvoidsecurity risks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary authentication through computational and Turing challenges before granting access to anonymous users. This preliminary action verifies user legitimacy and establishes temporary credentials, enabling easy access for authenticated users while preventing unauthorized access and mitigating security risks

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent dynamically changes access parameters by issuing time-limited temporary credentials with specific permissions to anonymous users. These credentials expire after a predetermined period or after a single use, allowing flexible accessibility while automatically revoking access to mitigate security risks

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10915253B2Temporary enrollment in anonymously obtained credentials
Publication Date: 2021.02.09 WORKDAY INC
  • US10915253B2 patent drawing
  • US10915253B2 patent drawing
  • US10915253B2 patent drawing

AI summary

A method begins by determining, by an authenticated device of a dispersed storage network (DSN), whether an access request from a requesting device is affiliated with an anonymous user or an authenticated user. When the requesting device is affiliated with the anonymous user, the method continues by determining, by the authenticated device, status of the anonymous user where the status of the anonymous user includes one of minimal threat, non-minimal threat, and significant threat. The method continues by processing, by the authenticated device, the access request in accordance with the status of the anonymous user.